Hardly a day goes by without the emergence of a disturbing new trend in cyber crime or headline-grabbing hack. Hackers are getting smarter and threat vectors are constantly evolving. The escalating threat is forcing businesses to file more cyber insurance claims than ever. But are they taking the proactive steps necessary to boost their security postures and become a better underwriting risk?
Cyber insurance claims double
According to a new study by AIG, claims frequency has spiked significantly. In 2018, there were as many cyber insurance claims as the previous two years combined, with business email compromise (BEC) overtaking ransomware as the primary claim.
Clearly, cyber insurance is fast becoming a “must-have” for any organization. However, because cyber incidents are becoming more complex and costly for insurers to investigate, companies are under increasing pressure to demonstrate a high standard of care when it comes to their security and third party management programs.
Insurers are careful to provide coverage to a business that is not aware of its own cyber security risk posture. Therefore, in seeking cyber insurance or filing a claim, companies must demonstrate that they are doing everything they can to protect themselves from attacks.
Here are some tactics that businesses can take to gain the trust of underwriters and protect themselves from the rising cost of cyber crime.
Adopt a hackers viewpoint
Organizations must work towards a greater understanding of how hackers see their network, including its systems, high-value targets, and vulnerabilities. By thinking like a cybercriminal and seeing what they see, organizations can better anticipate attacks before they occur.
To adopt this viewpoint, organizations must be more vigilant in visualizing and quantifying the performance of their cybersecurity program. With a better understanding of how their security apparatus is performing, organizations can also demonstrate a standard of care to their insurer which is beneficial in the event of a breach or compromise.
Be diligent with vendor selection
Currently, 59% of breaches originate with third-party vendors. Yet, organizations are struggling to make significant progress in managing cybersecurity risk in their supply chains because they lack transparency into the security posture of these partners. This blindspot of their enterprise security risk can cause them to fail to secure the right level and type of insurance coverage.